Privacy Policy
Last updated: September 1, 2026
This Privacy Policy explains what data NexusTrinityio LLC ("Nexus Trinity," "we," "us") collects through nexustrinity.io and related services (the "Service"), and what we do with it.
1. Data We Collect
We built this Service to collect as little personal data as possible. Specifically:
| Category | What's collected | Why | Where it's stored |
|---|---|---|---|
| Contract scan requests | The contract address and chain you query. This is public on-chain data, not personal data. | To fetch and analyze the contract | Supabase (Postgres), access-restricted |
| Sanctions Screening requests | The wallet or contract address you check, and whether it matched. This is public on-chain data, not personal data. | To run the check and enforce the free tool's daily limit | Supabase (Postgres), access-restricted |
| Rate-limiting | Your IP address, immediately SHA-256 hashed with a private salt — we never store your raw IP. | To enforce a fair daily usage limit on the free tools (Contract Reader and Sanctions Screening, tracked separately) and prevent abuse | Supabase, as a hash only |
| Report delivery (optional) | Your email address, only if you opt in to receive a report by email | To send you the report you requested | Supabase + Resend (our email provider) |
| Lead / "request a review" form | Name, email, and whatever you write in the message field | To respond to your inquiry about audit services | Emailed to us directly, and/or stored in Supabase as backup |
| API Access customers | Email, Stripe customer ID, Stripe subscription ID, a hash of your API key (never the raw key after initial issuance), and your two daily quota limits (Contract Reader, Sanctions Screening) | To authenticate API requests, enforce your quota, and manage billing | Supabase |
| API usage records | Which product (Contract Reader or Sanctions Screening) and address/chain you queried via the API, and when | To enforce your two daily quotas independently | Supabase, tied to your API key's internal ID only |
| API overage alerts | If you exceed either daily quota, we're notified by email so we can follow up — your request still succeeds regardless (see the API Terms of Service) | To let us proactively raise your limit rather than let you hit a wall | Resend, sent to us, not to you |
| Payment information | Handled entirely by Stripe. We never see or store your card number. | Billing | Stripe (not us) |
| Discord bot usage | The command you ran and its parameters (e.g., a contract address), as sent to us by Discord | To respond to your /check command | Not persisted beyond what's needed to answer; see §3 |
We do not require an account or login to use the free Contract Reader or the Discord bot. We do not track you across other websites, and we do not run advertising pixels.
2. How We Use Data
We use the data above only to: operate and improve the Service, respond to inquiries, deliver what you purchased, enforce usage limits and prevent abuse, and comply with legal obligations (e.g., tax records for payments via Stripe).
We do not sell your personal data. We do not share it with third parties for their own marketing purposes.
3. Third-Party Processors
We use the following third-party service providers, each of which processes a limited slice of the data above on our behalf, under their own privacy and security terms:
- Stripe — payment processing (subscriptions and one-time purchases)
- Supabase — database hosting (Postgres, with row-level security restricting what's readable)
- Resend — transactional email delivery (reports, lead notifications)
- Zoho Mail — outbound outreach email (only to recipients who have not unsubscribed; see §5)
- Groq — processes contract source code (public, on-chain data) to generate the free-tier Contract Reader analysis. Query text sent to Groq does not intentionally include your personal data.
- Anthropic — processes contract source code to generate the paid Deep Report analysis (a different, larger-context model than the free tier uses). Query text sent to Anthropic does not intentionally include your personal data.
- Etherscan (and equivalent block explorers) — source of the public contract source code we analyze
- Discord — delivers bot interactions; governed by Discord's own privacy policy for anything on their platform
- Vercel — application hosting
4. Data Retention
- Hashed IPs and scan records are retained to support rate-limiting and abuse prevention. We do not keep a plaintext log of who visited.
- Lead form submissions and email addresses tied to a purchase are retained as long as needed to respond to you and for our business records, and can be deleted on request (§7).
- API usage records are retained to support quota enforcement and are tied to an internal key ID, not directly to your email, in the usage table itself.
5. Email and Opt-Out
If you receive an email from us — a report, a digest, or outreach about our audit services — every message includes an unsubscribe link. Outreach emails are only sent to recipients who have not unsubscribed, and we honor unsubscribe requests immediately.
6. Security
API keys are never stored in plaintext — only a SHA-256 hash, the same approach used for banking and infrastructure API keys industry-wide. The raw key is shown to you exactly once, at issuance. Our database uses row-level security so that even a compromised anonymous credential cannot read or write scan or lead data directly — all writes go through server-side, service-role-authenticated code.
No system is perfectly secure, and we cannot guarantee absolute security of data transmitted to or stored by the Service.
7. Your Rights
You may request access to, correction of, or deletion of your personal data by emailing security@nexustrinity.io. We will respond within a reasonable time. If you are in the EU/UK or a US state with a specific data-rights statute (e.g., California), you may have additional rights under that law — contact us and we will address the request under the applicable framework.
8. Children's Privacy
The Service is not directed at children under 13, and we do not knowingly collect data from them.
9. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by an updated "Last updated" date.
10. Contact
NexusTrinityio LLC
security@nexustrinity.io